Signed URLs and hotlink protection for video, explained

How signed links and hotlink protection get bypassed: links shared before expiry, valid sessions, leaked secrets, public storage and faked Referer headers.

7 min read
On this page 9 sections
  1. What signed URLs and hotlink protection are
  2. How people get around signed links
  3. How people get around hotlink protection
  4. Warning signs to watch for
  5. What to ask your video platform or CDN provider
  6. The legal position
  7. Key takeaways
  8. Where VidSafe fits
  9. Frequently asked questions

A signed URL is a link with an expiry time and a tamper-proof signature, so the server delivering a file can tell that your platform issued the link and that nobody has changed or outlived it. Hotlink protection tries to stop other websites from using your files by checking where each request comes from. Both are useful filters, and both are routinely got around: signed links get shared before they expire or used inside a paying student's own session, and hotlink checks rely on a header that's easy to fake or leave out.

Think of a signed URL as a ticket printed for one show, valid until a set time. Your platform decides a student may open a file and issues a link carrying the conditions, such as which file and until when, plus a signature only your platform can produce, often using an HMAC; our explainer on how HMAC signs URLs covers the idea. Edit the link and the signature stops matching. Let the time pass and the link stops working.

  • Signed URL: the permission travels inside the link. Common for single files, such as a PDF.

  • Signed cookie: the permission travels in a cookie the browser sends with every request to the video domain, so one grant can cover many files.

  • Presigned URL: the term cloud storage services use for a signed link to a stored file, created with the credentials of whoever generated it.

Hotlinking is another website embedding or linking straight to your files, so that you pay for its traffic. Hotlink protection usually checks the Referer header, which says which page a request came from, and refuses requests from other sites.

A signature proves that your platform issued a link. It doesn't prove that the person using it is the person it was issued to. That gap, and the routes around the links, are where abuse happens:

  • Shared before expiry. A link copied into a Telegram group works for everyone in it until it expires. Links set to last for hours or days "to be safe" are effectively shareable links.

  • Not tied to a person. If a link works for whoever holds it, nothing distinguishes the student from the stranger they forwarded it to.

  • Used inside a valid session. Download tools running in a paying student's own browser fetch files while the student's access is perfectly valid. Signed links were never designed to stop that.

  • One grant, whole lecture. A streamed lecture is hundreds of small files, so platforms usually grant access to a whole lecture at once. A 90-minute lecture in 6-second pieces means 900 requests for each quality level watched. If that grant leaks, it opens the entire lecture until it expires.

  • Going around the front door. If the underlying storage still answers plain requests, the signed links are optional, and anyone who learns the storage address skips them entirely.

  • Leaked signing secrets. A signing secret left inside a mobile app, a web page or a public code repository lets anyone create valid links for any file, for as long as they like.

  • Old unsigned routes. An outdated app version, an old admin tool or a link in last year's email that was never signed keeps working after everything else is locked down.

  • No recall. Most signed links are checked by maths alone, so a leaked one can't be cancelled early; it works until its expiry.

  • The header is easy to fake. Nginx's documentation for its referer module says that faking a request with an acceptable Referer value "is quite easy", and that the module is meant to block the mass of ordinary browser requests, not every request.

  • The header is often missing. Browsers don't always send it and apps often don't, so hotlink rules usually have to allow requests with no Referer at all, which is exactly what a download tool can send.

  • It may not cover video. Some CDN hotlink features protect only image files. Cloudflare's Hotlink Protection, for example, applies to gif, ico, jpg, jpeg and png files, and lets requests with no Referer through.

  • Browser rules aren't access control. Cross-origin restrictions limit what other websites' scripts can read. They don't stop a download tool from fetching a file.

Hotlink protection stops casual embedding by other websites. It doesn't stop a determined person, and it was never meant to.

Warning signs to watch for

  • A lecture link posted in a Telegram group still plays hours or days later.

  • A link issued to one student plays for someone else, on another device or network.

  • Bandwidth bills rise faster than enrolments, or traffic arrives from websites you don't recognise.

  • Complete courses appear online soon after a batch opens, in clean, full quality.

  • Nobody on your team knows where the signing secrets are stored or who can reach them.

What to ask your video platform or CDN provider

  1. Can any video, key or PDF be fetched without signed, expiring access, including from old apps and admin tools?

  2. Is the underlying storage private, so nobody can go around the signed links?

  3. How long does access last, and does it end when a student's enrolment ends?

  4. Is access tied to the individual student, so a leaked link doesn't work for others and can be traced?

  5. Where are signing secrets kept, and are they ever shipped inside apps or web pages?

  6. Can signing secrets be rotated without breaking students' playback? Our guide to key rotation explains why this matters.

  7. What stops a paying student's own tools from saving lectures during a valid session? Our guides to stopping video downloads and HLS encryption cover that side.

Sharing a paid lecture without permission infringes copyright, however the link was obtained. Deliberately getting around technical protection with the intention of infringing can also be a criminal offence under Section 65A of the Copyright Act, punishable with up to two years in prison and a fine; our guide to copyright infringement punishment in India explains how it applies. This is general information, not legal advice. For your situation, speak to a lawyer.

Key takeaways

  • A signed URL proves your platform issued a link, not that the right person is using it.

  • Signed links are got around by sharing them before expiry, using them inside a valid session, leaking signing secrets or skipping them via public storage.

  • Hotlink protection relies on a header that's easy to fake and often missing, and may not cover video at all.

  • Long expiries, links not tied to a student and old unsigned routes are the warning signs.

  • Ask vendors specific questions; "our links are signed" is not an answer on its own.

Where VidSafe fits

Links leak, so what matters is what a leaked link can do. VidSafe protects course videos with VidSafe proprietary encryption, screen- and camera-recording detection and account-sharing prevention, and it adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See our LMS for coaching institutes.

Frequently asked questions

What is signed URL?

A signed URL is a link to a file that carries extra conditions, usually an expiry time, plus a cryptographic signature created by the platform that issued it. The server delivering the file checks the signature and refuses the request if the link was altered or has expired. It grants temporary access to private files, but it works for anyone who holds it until it expires.

How do signed URLs work?

Your platform decides that a user may access a file, then creates a link containing the file's location, an expiry time and sometimes other conditions, and signs them with a key only it controls. The delivery server verifies the signature and checks the time before serving the file. Because the check is mathematical, a leaked link keeps working until it expires.

What is presigned URL?

A presigned URL is a signed URL generated for a file in cloud storage, using the credentials of whoever created it. Anyone holding the link can download, or sometimes upload, that file until it expires, without needing their own account. On Amazon S3, for example, a presigned URL can last at most seven days, and less if the credentials behind it expire first.

Hotlink protection stops other websites from embedding or linking directly to your images or files, so you don't pay for their traffic. It usually works by checking the Referer header and blocking requests from other domains. It's a useful first filter, but the header is easy to fake and often absent, so it can't protect paid video on its own.

Share this article

Looking for something else?

Talk to Us